PULSE
FEED
ransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technologyransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technology
← All CVEs
CVE WatchOct 2, 2026

CVE-2026-103956

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain s

CVSS

10.0

Critical

EPSS

0.5%

p38

KEV

—

Exploit Today

11

0-100

Published: Oct 2, 2026 · Last modified: Oct 2, 2026 · CWE-306 · CWE-1188

EPSS · 30d
0.5%EPSS · 30 days0.5%
2026-10-032026-10-04
Technical description

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1051707.3 HIG
—
——0A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.10h
CVE-2026-1052079.8 CRI
—
——0ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.19h
CVE-2026-1051158.6 HIG
37.8%
——11OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.2d
CVE-2026-1051059.8 CRI
54.5%
——16CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.2d
CVE-2026-1050495.8 MED
11.6%
——3Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.2d
CVE-2026-951029.4 CRI
25.2%
——8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.2d